Skip to main content

Vendor archive

samsung CVEs

Beta · best-effort

1,628 CVEs tagged to vendor samsung113 Critical, 438 High, 965 Medium, 112 Low, 0 Unrated.

CVE-2016-1308

Published Feb 7, 2016

SQL injection vulnerability in Cisco Unified Communications Manager 10.5(2.13900.9) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8281

Published Jan 15, 2016

Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows attackers to bypass filesystem encryption via XOR calculations.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8280

Published Jan 15, 2016

Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to discover credentials by reading detailed error messages.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8279

Published Jan 15, 2016

Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to read arbitrary files via a request to an unspecified PHP script.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7897

Published Nov 16, 2015

The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2015-8040

Published Nov 2, 2015

The rtsp_getdlsendtime method in the CNC_Ctrl control in Samsung SmartViewer allows remote attackers to execute arbitrary code via an index value.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8039

Published Nov 2, 2015

Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors to the (1) DVRSetupSave method in the STWAxConfig control or (2) SendCustomPacket met…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4034

Published Jul 6, 2015

The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitrary files via a crafted Parcela…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4033

Published Jul 6, 2015

Samsung SBeam allows remote attackers to read arbitrary images by leveraging an NFC connection to access the HTTP server on port 15000.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-3435

Published May 1, 2015

Samsung Security Manager (SSM) before 1.31 allows remote attackers to execute arbitrary code by uploading a file with an HTTP (1) PUT or (2) MOVE request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-0555

Published Feb 24, 2015

Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrary code via a long string in t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1499

Published Feb 16, 2015

The ActiveMQ Broker in Samsung Security Manager (SSM) before 1.31 allows remote attackers to delete arbitrary files, and consequently cause a denial of service, via a DELETE reque…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9266

Published Dec 8, 2014

The STWConfig ActiveX control in Samsung SmartViewer does not properly initialize a variable, which allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9265

Published Dec 8, 2014

Stack-based buffer overflow in the BackupToAvi method in the CNC_Ctrl ActiveX control in Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vect…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8346

Published Oct 24, 2014

The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2014-3911

Published Jun 11, 2014

Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to the (1) Start, (2) ChangeControlLocalName, (3) DeleteDevicePr…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-3912

Published Jun 5, 2014

Stack-based buffer overflow in the FindConfigChildeKeyList method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control in Samsung iPOLiS Device Manager before 1.8.…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6429

Published Apr 4, 2014

Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to execute arbitrary code via a lon…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-3964

Published Oct 1, 2013

Cross-site scripting (XSS) vulnerability in Samsung SHR-5162, SHR-5082, and possibly other models, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3585

Published Aug 28, 2013

Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) dire…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,576-1,600 of 1,628 CVEsPage 64 of 66